hardMultiple Select
CS0-003 Practice Question: Which TWO of the following are indicators of…
Which TWO of the following are indicators of potential data exfiltration via DNS?
⚠ Common exam trap
CompTIA often tests the distinction between DNS tunneling indicators (TXT record volume and long subdomains) and other DNS anomalies like NXDOMAIN responses, which are more associated with DGA or reconnaissance rather than exfiltration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
High volume of TXT record queries
TXT records are commonly used in DNS tunneling to encode exfiltrated data. Attackers embed data in TXT record queries or responses, and a high volume of such queries is a strong indicator of data exfiltration via DNS.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Unusual TLS handshake patterns
Why it's wrong here
While anomalies in TLS handshakes can indicate encrypted command-and-control (C2) communication or data exfiltration over HTTPS, they occur at the transport and presentation layers and are entirely separate from the DNS protocol. DNS queries typically run over UDP port 53 without TLS, unless DNS-over-TLS (DoT) is specifically configured, making TLS handshake patterns irrelevant to standard DNS exfiltration detection.
- ✗
Traffic to known malicious IPs over HTTP
Why it's wrong here
Direct HTTP traffic to known malicious IP addresses indicates web-based command-and-control (C2) activity or standard web-based data exfiltration. This type of traffic does not leverage the DNS protocol as a covert channel, which is the primary mechanism for DNS-based exfiltration where data is embedded within queries to authoritative nameservers.
- ✗
Large number of NXDOMAIN responses
Why it's wrong here
A high volume of NXDOMAIN (Non-Existent Domain) responses typically points to malware utilizing Domain Generation Algorithms (DGAs) to locate active C2 servers, or aggressive network scanning. While suspicious, it indicates a failure to resolve domains rather than the successful, bidirectional data transfer characteristic of active DNS exfiltration.
- ✓
High volume of TXT record queries
Why this is correct
Attackers frequently abuse DNS TXT records because they can hold large, arbitrary strings of text, making them ideal for carrying payload data or receiving commands. A sudden spike in TXT queries, especially to unfamiliar external domains, strongly suggests that an internal host is using these records to bypass traditional firewalls and exfiltrate sensitive data.
- ✓
Frequent queries to long subdomains
Why this is correct
DNS exfiltration techniques often prepend encoded data (such as Base64 strings) to the domain name as a subdomain, resulting in unusually long and complex query strings. When these queries reach the attacker's authoritative nameserver, the server decodes the subdomain portion to reconstruct the stolen data, making frequent queries to long subdomains a primary indicator of compromise.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.